Privacy Policy
A Digital Towns Ltd Product
This document has been drafted to comply with the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the EU GDPR (Regulation 2016/679), and the EU AI Act (Regulation 2024/1689).
TechLocal is a digital platform operated by Digital Towns Ltd, a company registered in England and Wales.
- Company name: Digital Towns Ltd
- Registered address: Launchpad, Teesside University, Middlesbrough, TS1 3BX
- ICO Registered: Digital Towns Ltd
- Data Controller contact: privacy@techlocal.uk
- Platform website: www.techlocal.uk
Digital Towns Ltd is the Data Controller for all personal data processed through TechLocal. Where we act on behalf of third parties such as employer organisations, we may also act as a Data Processor; separate data processing agreements will be in place for such arrangements.
This Privacy Policy applies to all users of TechLocal including:
- Students and graduates who create talent profiles
- Employers and hiring organisations who access the platform
- Visitors to www.techlocal.uk who browse without registering
- University partners and institutional users
It covers all personal data collected through our website, web application, email communications, and any future mobile applications or integrations.
3.1 Students and Graduates
- Full name, preferred name, and profile username
- University email address and personal email address
- University name, course title, year of study, and expected graduation date
- Skills, competencies, and category selection
- Portfolio items including project descriptions, titles, and links
- Profile photograph (optional)
- CV or resume documents (optional, uploaded as PDF)
- Work preferences: availability, work type, and location preferences
- LinkedIn profile URL, GitHub, or portfolio URL (optional)
- Custom skill tags: free text, up to 3 entries
- Account activity: login timestamps, profile view counts, contact request history
- Communication records: messages exchanged through the platform contact system
3.2 Employers and Hiring Organisations
- Company name, registered address, and company number if applicable
- Contact person name, job title, and work email address
- Industry sector and organisation size
- Account activity: login timestamps, profiles viewed, contact requests sent
- Credit purchase records and transaction history
- Communication records through the platform contact system
3.3 Technical and Usage Data (All Users)
- IP address and approximate geographic location
- Browser type, version, and operating system
- Pages visited, time on page, and navigation paths
- Device type and screen resolution
- Session identifiers and authentication tokens
3.4 Data We Do Not Collect
We do not collect special category data as defined in Article 9 UK GDPR or EU GDPR unless you voluntarily include it in free-text fields such as a CV or project description. Special category data includes racial or ethnic origin, religious beliefs, political opinions, trade union membership, genetic or biometric data, health or disability data, and sexual orientation. If you include such data voluntarily, we treat it with heightened care under Article 9.
We process your personal data only where we have a lawful basis under Article 6 UK GDPR or EU GDPR, and Article 9 for special category data where applicable.
4.1 Core Platform Operations
- Create and manage your account — Lawful basis: Contract, Art. 6(1)(b)
- Display your student profile to verified employers — Lawful basis: Contract, Art. 6(1)(b)
- Facilitate contact requests between employers and students — Lawful basis: Contract, Art. 6(1)(b)
- Process credit purchases and returns — Lawful basis: Contract, Art. 6(1)(b)
- Send transactional emails such as account confirmation, contact notifications, and password reset — Lawful basis: Contract, Art. 6(1)(b)
4.2 Platform Improvement, Research, and Educational Purposes
We process aggregated and, where necessary, pseudonymised personal data for internal research and educational purposes to improve TechLocal and to develop new platform features. This includes:
- Analysing which skills and categories are most in demand by employers in a given region
- Understanding how students interact with profile-building features to improve usability
- Developing and training AI-assisted matching and recommendation features solely for the benefit of users on this platform
- Generating anonymised statistical reports shared with university partners
- Conducting internal academic-style research into regional technology and digital talent markets to inform product development
Lawful basis: Legitimate Interests under Art. 6(1)(f) UK GDPR and EU GDPR. We have conducted a Legitimate Interests Assessment (LIA) in accordance with ICO guidance.
4.3 Safety, Security, and Legal Compliance
- Detect and prevent fraud, abuse, or misuse — Lawful basis: Legitimate Interests, Art. 6(1)(f)
- Comply with legal obligations including ICO requirements — Lawful basis: Legal Obligation, Art. 6(1)(c)
- Respond to court orders, law enforcement, or regulatory investigations — Lawful basis: Legal Obligation, Art. 6(1)(c)
4.4 What We Will Never Do With Your Data
- Sell your personal data to any third party under any circumstances
- Share individually identifiable data with advertisers or for advertising purposes
- Use your data for behavioural advertising or profiling for marketing purposes
- Transfer your data outside the UK or EU without adequate safeguards
- Use your data to make solely automated decisions with legal or similarly significant effects without human review
- License, sell, or share your data to train AI models for use by third parties
Where we rely on consent as a lawful basis, for example for optional marketing communications, you have the right to withdraw consent at any time without detriment. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent: email privacy@techlocal.uk or use account settings. Withdrawing optional processing consent does not affect your ability to use core platform features.
7.1 With Employers (Students Only)
Your public profile including your name, university, skills, portfolio, and stated preferences is visible to verified employer accounts. Employers cannot access your CV or contact you without spending a credit, and you can decline any contact request.
7.2 Third-Party Service Providers (Data Processors)
We use the following sub-processors, all bound by Data Processing Agreements and processing data only on our instructions:
- Supabase Inc. — Database and file storage. Data hosted in AWS eu-west-2, London, UK
- Vercel Inc. — Web hosting and deployment. Data routed through lhr1, London region
- Resend Inc. — Transactional email delivery. EU data centre
- Stripe Inc. — Payment processing for credit purchases. PCI-DSS compliant
7.3 University Partners
We share aggregated, anonymised statistical reports only. No individually identifiable data is shared.
7.4 Legal Disclosures
We may disclose personal data to law enforcement, regulators including the ICO, or courts where required by law, court order, or regulatory requirement.
7.5 Business Transfers
If Digital Towns Ltd is involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that transaction. We will provide notice before any such transfer and ensure the receiving organisation upholds equivalent data protection standards.
All primary data storage and processing takes place within the UK (eu-west-2, London) or the European Economic Area. Where any third-party service provider transfers data to the US or other third countries, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) for EU personal data and UK International Data Transfer Agreements (IDTAs) for UK personal data. Copies of relevant safeguards are available at privacy@techlocal.uk on request.
- Active student profiles: retained while account is active plus 2 years after last login
- Inactive accounts: we contact you after 2 years of inactivity; no response within 30 days results in full deletion
- Contact request records: deleted 12 months from the date of the request
- Credit transaction records: retained for 7 years to comply with UK financial record-keeping obligations
- Server logs and technical data: retained 90 days then deleted
- Anonymised and aggregated research data: may be retained indefinitely as it cannot identify individuals
Upon deletion, data is securely erased from live systems. Backup deletion occurs within 90 days.
10.1 Right of Access
Request a copy of all personal data we hold about you. We respond within one calendar month, free of charge.
10.2 Right to Rectification
Request correction of inaccurate or incomplete personal data. Most data can be corrected directly in your account settings.
10.3 Right to Erasure
Delete your account at any time through Settings > Delete Account. This permanently removes your profile, uploaded files, and contact history. Some data is retained where required by law.
10.4 Right to Restrict Processing
Request restriction of processing in certain circumstances, for example while an accuracy dispute is resolved.
10.5 Right to Data Portability
Download your personal data in a structured, machine-readable JSON format via Settings > Export My Data.
10.6 Right to Object
Object to processing based on legitimate interests, including research and platform improvement. Where you object, we will cease that processing unless we can demonstrate compelling legitimate grounds. Email privacy@techlocal.uk to object.
10.7 Rights in Relation to Automated Decision-Making
We do not make solely automated decisions with significant legal or similar effects on individuals. All AI-assisted features operate as advisory tools with human oversight maintained at all decision points.
10.8 How to Exercise Your Rights
- Email: privacy@techlocal.uk with subject line: Data Subject Rights Request
- We verify your identity before processing any request
- Response within one calendar month, extendable by two further months for complex requests
11.1 Current AI Features
- Profile quality suggestions: optional informational recommendations to help students improve profiles
- Search and filtering: algorithmic ranking of profiles in employer search results based on stated search criteria
11.2 AI Risk Classification
All current AI features are classified as Limited Risk under the EU AI Act (Regulation 2024/1689). They do not fall within the High-Risk categories in Annex III.
11.3 Transparency
AI-generated content or AI-assisted features are clearly labelled in the interface in accordance with Article 50 of the EU AI Act. See our AI Transparency page for more details.
11.4 Human-in-the-Loop
We maintain human oversight in all AI-assisted processes. No AI system makes final decisions about employment, access to opportunities, or individual scoring.
11.5 Future AI Development
As we develop additional AI features, we will update this policy, conduct Data Protection Impact Assessments where required, and re-assess AI risk classifications before deployment.
- All data in transit encrypted using TLS 1.2 or higher
- All data at rest encrypted using AES-256
- Row-level security (RLS) enforced at the database level
- Role-based access controls limiting internal staff access to personal data
- Supabase infrastructure in AWS eu-west-2, London, with SOC 2 Type II certification
- Incident response plan in place with defined escalation procedures
12.1 Data Breach Notification
In the event of a personal data breach likely to result in risk to your rights and freedoms, we notify the ICO within 72 hours as required by Article 33 UK GDPR. Where a breach poses high risk to you personally, we will also notify you directly without undue delay.
TechLocal is for university students and graduates. We do not knowingly collect personal data from individuals under 16. In accordance with the Data Protection Act 2018 and the Children's Code, we apply heightened protections to users aged 16 to 17. If we become aware of data collected from a child under 16 without verified parental consent, we will delete it promptly.
UK Users
- Information Commissioner's Office: www.ico.org.uk
- Telephone: 0303 123 1113
- Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
EU Users
EU data subjects may lodge complaints with their national data protection authority. A list is at edpb.europa.eu.
We welcome the opportunity to resolve any complaint directly. Please email privacy@techlocal.uk in the first instance.
We review and update this Privacy Policy whenever there is a material change to how we process personal data. We notify registered users of material changes by email at least 30 days before changes take effect. The current version is always at www.techlocal.uk/privacy.
- Email: privacy@techlocal.uk
- Post: Data Controller, Digital Towns Ltd, Launchpad, Teesside University, Middlesbrough, TS1 3BX
- Response time: within 5 business days for general queries; within one calendar month for formal data subject rights requests
Contact Data Protection Officer
Have questions about how we handle your data? Our Data Protection Officer is here to help.
privacy@techlocal.ukTechLocal is a product of Digital Towns Ltd. Registered in England and Wales.